Rendered at 17:42:02 GMT+0000 (Coordinated Universal Time) with Cloudflare Workers.
throwaway27448 18 minutes ago [-]
What is rustdesk and how is it distinct from vnc?
vablings 14 minutes ago [-]
Well first there was TeamViewer which was VNC with more bells and whistles then it became enshittified. Then anydesk came along and ate up teamviewer then that became enshittified, Now we have rustdesk which seems to hopefully be a bit more immune to being enshittified.
If you already use VNC this is not something for you
ChocolateGod 16 minutes ago [-]
How does this work on a technical level?
Does it framebuffer grab the current session and inject input events?
andai 54 minutes ago [-]
Menu css looks a bit dodgy with the notification at the top:
It's open-source, so just build it yourself with the tiny change. Something this trivial could be done with a 30 second prompt at this point, so there's not even an excuse of "too much effort".
I will note that the XKCD password scheme being proposed there is, in fact, completely insecure. A modern consumer GPU can crack "four random English words" in a day. You can argue that it's the user's choice to be allowed to use insecure passwords, but arguing that that scheme is actually secure is just wrong.
tredre3 7 minutes ago [-]
> A modern consumer GPU can crack "four random English words" in a day. [...] but arguing that that scheme is actually secure is just wrong.
Let me do just that!
This is a networked service. You send your password (or a hashed form) to it, and it validates it. You don't have the local hash to bruteforce it offline.
Even if we only consider the top 10k english words, it's 10000^4. It's going to take years to bruteforce this over a network because you'll go through so many rate-limits, cooldown periods, and outright bans that it's questionable whether it's even possible.
throwaway27448 17 minutes ago [-]
> A modern consumer GPU can crack "four random English words" in a day.
Sure, if you can rely on users using a specific format. The joy of the xkcd technique is you don't need to tell other people what yours is.
But, people just aren't going to remember strings of gibberish. Expecting users to do this is just silly.
applfanboysbgon 11 minutes ago [-]
The "joy of the XKCD technique" is that it prescribes a specific format millions of people will use, and it's so trivial to break that you can throw in similar variations of it into your cracking algorithm at virtually no cost.
If you were willing to use a bespoke, more secure variation of it, you could include a capital letter and a number rather than filing an issue on a repo insisting that you be allowed to use exactly the insecure variation.
zuzululu 56 minutes ago [-]
so this means I can be on a vacation, turn on my ubuntu desktop remotely, login and control it ? I have a strong need for this as my desktop is also a server
VorpalWay 30 minutes ago [-]
For a remote Linux system you can also do a lot over plain SSH as well.
amelius 33 minutes ago [-]
You can already do this with VNC or Xpra (the latter is a screen/tmux for graphical applications).
If you already use VNC this is not something for you
Does it framebuffer grab the current session and inject input events?
https://files.catbox.moe/d5ztxi.jpg
I will note that the XKCD password scheme being proposed there is, in fact, completely insecure. A modern consumer GPU can crack "four random English words" in a day. You can argue that it's the user's choice to be allowed to use insecure passwords, but arguing that that scheme is actually secure is just wrong.
Let me do just that!
This is a networked service. You send your password (or a hashed form) to it, and it validates it. You don't have the local hash to bruteforce it offline.
Even if we only consider the top 10k english words, it's 10000^4. It's going to take years to bruteforce this over a network because you'll go through so many rate-limits, cooldown periods, and outright bans that it's questionable whether it's even possible.
Sure, if you can rely on users using a specific format. The joy of the xkcd technique is you don't need to tell other people what yours is.
But, people just aren't going to remember strings of gibberish. Expecting users to do this is just silly.
If you were willing to use a bespoke, more secure variation of it, you could include a capital letter and a number rather than filing an issue on a repo insisting that you be allowed to use exactly the insecure variation.